Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RioAung
Contributor

How to export basic config and import to new firewalls

Hi,

I have multiple site to deploy .So I would like to standard config for every site.

I want to export basic setting like stealth rule, hardening setting, manangement IP and password ,etc. and then i want to import other firewall. what kind of function can i use ? if i use backup function and import to other firewall,I got stability issue . i used dbset backup:override_hfs t to fix if i got the errror.

 

let me know any best way to import standard setting.

0 Kudos
7 Replies
G_W_Albrecht
Legend Legend
Legend

See here: sk108902 - Best Practices - Backup on Gaia OS.

But i would suggest that the best solution for you is sk120193: Blink - Gaia Fast Deployment !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
_Val_
Admin
Admin

Not sure about stealth rule, that is always on the MGMT side.

For the rest, could you elaborate on backup function and stability issues?

For the most basic things, I would use "show config" in clish and then copy/paste to the new FW.

0 Kudos
PhoneBoy
Admin
Admin

What precisely are you migrating from in terms of hardware and software versions?
What precisely are you migrating to in terms of hardware and software versions?
How is the gateway managed? (Stand-alone or distributed)
The precise steps will depend on the answer to those questions, but will most likely involve the standard migration tools. 

0 Kudos
RioAung
Contributor

Hi @PhoneBoy ,

I have multiple site and all site are using same models and some basic rule are same . all are using same hardening config. I don't want to do hardening for every appliance . Blink deployment is only can include basic config like password , IP, SIC information ,right.

So i would like to export standard config including hardening config and import to other devices.

 

0 Kudos
PhoneBoy
Admin
Admin

Access and Threat Prevention policies comes from the management, so it's just a matter of installing the same policy to the different devices.
If you configured anything in Gaia OS using clish, that can be replicated easily enough with blink and/or CDT as mentioned in this thread.
You may also want to leverage CDT's "RMA" mode: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

0 Kudos
the_rock
Legend
Legend

I know sk @G_W_Albrecht provided you is definitely good start, but I would add that statement in it saying that backup can be imported into a different hardware model is not factually true. Say if you have 6000 appliance, but want to restore that backup on say 13000 series appliance, that would most likely not work. Personally, I would go with show configuration output from clish, as I find that easiest way to quickly get box up and running.

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Personally, i would go with blink and create deployment templates !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events